ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 9 sources: “Cisco Patches Nine Secure Firewall ASA/FTD Vulnerabilities, Including ACL Bypass and Eight Denial-of-Service Flaws” — merged summary and timeline →

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

mediumAdvisoryimportance 45
AI summary · glm-5.3-flash

Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.

A vulnerability in the VPN and management web servers of Cisco ASA Software and Cisco Secure FTD Software allows an unauthenticated remote attacker to exhaust system memory or buffer blocks, causing a denial of service. Originally scoped to the ASAv and FTDv virtual appliances, Cisco updated the advisory on September 16, 2026 to cover all ASA and FTD platforms.

  • Unauthenticated remote attackers can exhaust system memory or buffer blocks
  • Initially believed limited to ASAv and FTDv virtual appliances
  • Updated advisory now covers all ASA and FTD software platforms
Full article

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.